TL;DR: consent-granted script behavior drift monitoring
- A cookie banner is a paper trail, not a privacy control. A tag consented to for analytics can quietly start reading payment form fields the following week, and the CMP still shows a green tick.
- cside Privacy Watch tracks which DOM elements each script touches, which endpoints it calls, and what changes since its last approved baseline, and it is VikingCloud-validated for PCI DSS 4.0.1 Req 6.4.3 and 11.6.1.
- If you already run OneTrust or Cookiebot for consent documentation, add runtime coverage alongside. If PII exfiltration by a rogue pixel is not on your risk register, do not.
Privacy monitoring software splits into two categories that are easy to confuse. Consent management platforms (CMPs) control which cookies get set and record user consent choices. Script behavior monitors watch what third-party JavaScript actually does inside the browser: whether it reads form fields, accesses user data, or sends information to destinations it was never approved for. The two solve different problems. A site with a compliant cookie banner and an unmonitored marketing stack can still exfiltrate customer PII in ways that trigger GDPR enforcement and PCI DSS violations.
Here is how the main options compare on the capability most buyers overlook: real-time visibility into script behavior.
| Tool | Primary function | Real-time script behavior monitoring | PCI DSS 4.0.1 script integrity (Req 6.4.3, 11.6.1) | Free tier |
|---|---|---|---|---|
| cside Privacy Watch | Third-party script behavior, data access, and network calls | Yes | Yes (validated) | Yes, 1,000 API calls/mo |
| OneTrust | Consent management, data mapping, vendor risk workflows | Consent layer, not runtime | Consent documentation layer | Enterprise (contact sales) |
| Cookiebot | Cookie scanning and consent banner management | No | Not covered | Free scan for small sites |
Why cookie consent is not privacy monitoring
A consent management platform records that a user accepted or declined cookie categories. It does not watch what the approved scripts do after they load. A marketing pixel that is included in the "analytics" consent category, then later updated by the vendor to also collect form field data, is invisible to the CMP. The user consented to analytics tracking, not to form data harvesting, but the CMP only sees that consent was granted to the category.
This is the gap that produces GDPR enforcement actions even for organizations with well-configured consent banners. Often the exposure sits in what the scripts do at runtime. A script can hold valid consent and still start reading data or calling endpoints it was never approved for.
PCI DSS 4.0.1 Requirement 6.4.3 formalizes this distinction by requiring that all scripts on payment pages be inventoried, authorized, and monitored for integrity. A consent banner satisfies none of those requirements on its own.
cside Privacy Watch: script behavior monitoring
cside Privacy Watch monitors the behavior of every third-party script loaded on a page in real time. It tracks which DOM elements each script accesses, which network destinations it calls, what data it reads from form fields, and whether its behavior has changed since it was last reviewed and approved.
When a script that was approved for analytics begins accessing payment form fields or sending data to a new endpoint, cside detects the change and alerts in real time. That matters for GDPR compliance, where scripts must behave within the scope of the consent given, and for PCI DSS 4.0.1, where script integrity on payment pages has been a mandatory control since March 2025.
cside Privacy Watch is validated by VikingCloud for PCI DSS 4.0.1 Requirements 6.4.3 and 11.6.1. The monitoring output satisfies the specific evidentiary requirements of those controls, not just the general intent.
$4.88 million: the global average cost of a data breach in 2024, with 46% of breaches involving customer PII. Third-party script exfiltration is one of the primary vectors for web-based PII exposure. Source: IBM Cost of a Data Breach Report 2024
OneTrust
OneTrust is a broad privacy compliance platform covering consent management, data mapping, vendor risk assessment, and regulatory workflow management. It is widely used for enterprise compliance programs.
For script behavior specifically, OneTrust operates at the consent layer. It manages which scripts are deployed and records consent decisions. It is not built to perform real-time monitoring of what those scripts do once loaded, so a script that changes behavior after consent is granted, by accessing additional data or calling new endpoints, sits outside its scope. Teams that need runtime script monitoring alongside consent management typically pair OneTrust with a separate tool for that layer.
Cookiebot
Cookiebot provides cookie scanning, consent banner management, and compliance reporting for GDPR and CCPA. It is commonly deployed in small and mid-sized organizations as an accessible consent solution.
Like OneTrust, Cookiebot is a consent management platform. It inventories the cookies a website sets and lets users manage their preferences by category. It is not designed to monitor script behavior at runtime, detect data exfiltration, or produce PCI DSS 4.0.1 script integrity evidence. For organizations whose primary need is cookie consent documentation, Cookiebot fits that job well. Organizations that also need to know what their scripts do after consent is granted will need to add runtime coverage.
Choosing the right tool
For most organizations the right combination is a CMP for consent documentation plus a script behavior monitor for runtime coverage. They address different risks and are not substitutes for each other. A CMP that only manages consent leaves the runtime gap open, and a script monitor that never records consent decisions leaves your regulatory paper trail incomplete.
For PCI-scoped pages, Requirement 6.4.3 mandates both a script inventory (which a CMP partially addresses) and integrity monitoring (which requires a runtime tool). cside satisfies both in a single validated deployment. You can start on the free tier of 1,000 API calls per month with no credit card, then move to the Business plan at $99/month or Enterprise custom pricing as coverage grows. See pricing for details.
Further reading
- cside Privacy Watch for real-time third-party script monitoring
- PCI DSS compliance for Requirements 6.4.3 and 11.6.1 script integrity
- Best AI tools for website privacy compliance








